PT-2026-82111 · Veeam · Veeam One
CVE-2026-65641
·
Published
2026-08-26
·
Updated
2026-08-27
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Veeam ONE versions prior to 13.1.0.7233
Veeam ONE versions prior to 13.0.2.7159
Description
An unauthenticated network attacker can coerce the Veeam ONE service account into performing SMB (Server Message Block) authentication. This action potentially exposes NTLM (New Technology LAN Manager) credentials, which are used for authentication in Windows environments.
Recommendations
Update to version 13.1.0.7233.
Update to version 13.0.2.7159.
Fix
Authentication Bypass Using an Alternate Path or Channel
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Veeam One